This documentation supports the 21.3 version of BMC Helix Single Sign-On.To view an earlier version, select the version from the Product version menu.

Self-service configuration for BMC Helix SSO Tenant administrator



As a Tenant Administrator, you can perform the following list of operations in the BMC Helix SSO:

  • audit records.
  • manage sessions (view or delete existing sessions).
  • configure IdP settings and managing branding in allowed for self service realms.

A self service configuration allows Tenant Administrators to perform administrative operations available in BMC Helix SSO autonomously. 

To configure self service in the Tenant

  1. As a SaaS administrator, log in to the BMC Helix SSO Admin Console.
  2. On the navigation panel, click Tenant.
  3. In the Self service configuration field, select the IdPs that need to be available for the all tenant`s realms from the following json string example: 

{"allowedIdPs":["LOCAL","SAML","LDAP","OIDC","PREAUTH"],"bypassTemplate":{"host":"localhost","port":0}}

The Self service configuration field contains bypassTemplate configuration which is used to configure bypass for all realms allowed for a self service. Here, you can change values for the host and port, otherwise the default configurations will be applied. In case when a new tenant is created via HSSO Admin Console, a bypass template configuration and LOCAL, SAML, LDAP, OIDC, PREAUTH allowed IdPs are available. The self service configuration is optional. If no configuration provided than all IdPs will be allowed for configuration.

image2021-9-16_8-6-47.png

To configure self service in the Realm

After the configurations in the Tenant are done, navigate to the appropriate Realm to configure a self services for.

  1. From the list of the Realms, select the necessary one.
  2. Click Edit Realm.
  3. Select the Self service checkbox.
  4. Save your changes.

Note

By default, all existing or newly created realms are disabled for a self service configuration.

The three tabs become available for a Tenant Administrator in addition to existed Local User management:

  • Realm - make changes for branding, update Authentication settings (with no access to information about bypass)
  • Session - get information about existed sessions, manage them (delete)
  • Audit - to get data about admin and end-user audited actions

image2021-9-17_9-52-25.png


 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*